Skip to content

Fix resolveLatestTag() using an unauthenticated GitHub API call - #120

Merged
webbertakken merged 1 commit into
mainfrom
fix/resolve-latest-cli-uses-action-token
Sep 16, 2026
Merged

webbertakken merged 1 commit into
mainfrom
fix/resolve-latest-cli-uses-action-token

Conversation

@frostebite

@frostebite frostebite commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Summary

resolveLatestTag() (used to resolve cliVersion: latest to a concrete release tag) hit the GitHub API unauthenticated for effectively every consumer, because GITHUB_TOKEN/GH_TOKEN are not automatically injected into a custom JS action's process environment — a calling workflow has to set them explicitly via env:, which essentially no consumer had reason to do. This exhausts the shared unauthenticated rate limit (60 req/hour per runner IP) under any real concurrency, e.g. a multi-version test matrix all resolving "latest" at once.

Confirmed live via a Mirror Networking Actions run failing with "GitHub API returned 403", and this is the identical root cause already fixed in unity-test-runner#332 and unity-builder#852 — this PR applies the same fix to unity-activate, the third and final thin wrapper.

Changes

  • Adds a githubToken input to action.yml, defaulting to ${{ github.token }} (populated by GitHub Actions on every run — no consumer action needed).
  • Threads it through index.ts → downloadCli() → resolveLatestTag(), sent as Authorization: Bearer <token>, ahead of the GITHUB_TOKEN/GH_TOKEN env-var fallback.
  • Extends the existing src/download-cli.test.ts with regression tests covering: no Authorization header when nothing is set, the header from the githubToken parameter, the env-var fallback, and that downloadCli() actually forwards the parameter through to resolveLatestTag() (the production wiring, not just the isolated function).

Test plan

  • New/updated tests confirmed to fail when the fix is reverted (3 tests fail cleanly, isolating exactly the auth behavior)
  • Full suite green: 23/23 tests passing
  • tsc --noEmit clean
  • yarn lint clean (only pre-existing, unrelated any warnings)
  • yarn build (ncc) succeeds; dist/index.js verified to contain the fix
  • action.yml validated as well-formed YAML

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added an optional GitHub token setting for authenticating requests when resolving the latest CLI version.
    • The token defaults to the workflow’s GitHub token and can be overridden when needed.
    • Latest-version downloads now use authentication when a token is available, helping reduce failures caused by GitHub API rate limits.
    • Existing environment-based tokens are also supported when no input token is provided.
  • Tests

    • Added coverage for token forwarding, authorization headers, and fallback behavior.

GITHUB_TOKEN/GH_TOKEN are not automatically injected into a custom JS
action's process environment - a calling workflow has to set them
explicitly via env:, which essentially no consumer had reason to do.
So resolving cliVersion: latest hit the GitHub API unauthenticated for
effectively every consumer, exhausting the shared 60 req/hour rate
limit under any real concurrency (e.g. a multi-version test matrix).

Confirmed live via a Mirror Networking Actions run and the identical
bug already fixed in game-ci/unity-test-runner#332 and
game-ci/unity-builder#852.

Adds a githubToken input (default: ${{ github.token }}, populated by
Actions on every run with no consumer action needed) and threads it
through downloadCli -> resolveLatestTag ahead of the env-var fallback.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1e61308d-c5ac-401a-ae97-4df9a1604c99

📥 Commits

Reviewing files that changed from the base of the PR and between 3d588e5 and 4523324.

⛔ Files ignored due to path filters (2)
  • dist/index.js is excluded by !**/dist/**
  • dist/index.js.map is excluded by !**/dist/**, !**/*.map
📒 Files selected for processing (4)
  • action.yml
  • src/download-cli.test.ts
  • src/download-cli.ts
  • src/index.ts

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The action adds an optional githubToken input. Runtime code forwards the token to latest CLI version resolution. GitHub API requests use the token from the input or environment variables. Tests cover authenticated and unauthenticated requests.

Changes

GitHub token resolution

Layer / File(s) Summary
Token input and runtime wiring
action.yml, src/index.ts, src/download-cli.ts
The action declares githubToken with a ${{ github.token }} default. run() reads the input and forwards it to downloadCli().
Authenticated latest-version lookup
src/download-cli.ts, src/download-cli.test.ts
resolveLatestTag() adds an Authorization: Bearer header when a token is available from the parameter or environment. Tests cover explicit, fallback, and absent tokens.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant GitHubAction
  participant run
  participant downloadCli
  participant resolveLatestTag
  participant GitHubAPI
  GitHubAction->>run: Read githubToken input
  run->>downloadCli: Pass cliVersion and githubToken
  downloadCli->>resolveLatestTag: Resolve latest tag
  resolveLatestTag->>GitHubAPI: Send request with optional Bearer token
  GitHubAPI-->>resolveLatestTag: Return latest tag
Loading

Merge Risk: ⚪ Minimal · up to 45233

The token input and latest-version lookup changes have no identified merge-blocking risk in the reviewed scope.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 3 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: adding authentication to resolveLatestTag() GitHub API requests.
Description check ✅ Passed The description clearly explains the problem, implementation, and validation results. It includes Changes and testing information, but it does not use the exact template headings or include the contri…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 3 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/resolve-latest-cli-uses-action-token

Warning

Git: CodeRabbit could not clone the repository, so clone-backed analysis was skipped and this review may be incomplete. Verify repository clone access, such as SSH credentials, before requesting another full review. If clone access is intentionally unavailable, use path_filters to narrow the review scope.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@webbertakken
webbertakken merged commit 2e3cdcc into main Sep 16, 2026
8 checks passed
@webbertakken
webbertakken deleted the fix/resolve-latest-cli-uses-action-token branch September 16, 2026 10:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants